SECURITY & CONTROL

Trust starts with
clear boundaries.

A security-oriented engineering approach, explicit responsibilities and honest certification boundaries. Not a badge in place of evidence.

ENGINEERING APPROACH

Controls belong
throughout the lifecycle.

The product design describes the following control areas. Deployment evidence and independent assessments must verify the implementation.

Identity & access

Role-based access, tenant isolation and server-side permission checks for supported actions.

Sensitive-data boundaries

Controlled credential handling, PAN protection and secure logging. CVV is never persisted after authorization.

Service communication

Transport security and service authentication, with mTLS where required by the integration model.

Secrets & cryptography

Controlled runtime secrets and an HSM abstraction for applicable payment cryptographic operations.

Audit & change control

Traceable operational actions and configuration changes, with required approvals in the agreed scope.

Financial recovery

Explicit idempotency and recovery semantics for duplicate or ambiguous payment scenarios.

Operational resilience

Monitoring, escalation, backup and recovery requirements validated against the planned deployment.

Shared responsibilities

Document responsibilities across MerchantPaisa, your organization, processors, sponsors and other providers.

CERTIFICATION IS A SEPARATE GATE

Engineering intent
is not certification.

The source marketing baseline describes a PCI DSS v4.x-oriented engineering architecture. This website does not claim a formal PCI DSS attestation or completed external scheme certification.

Internal validationEngineering tests and pre-certification support preparation.

External verificationScheme, sponsor and security requirements need the appropriate evidence and approval.

Production releaseBusiness, operational and technical sign-off remain distinct launch requirements.

START WITH RESPONSIBILITIES

Build an evidence-backed
release plan.

Review the go-live planner with the teams responsible for security, processing, operations and the regulated operating model.

Open the go-live planner

Public descriptions are not a security assessment. Request current implementation evidence and the responsibility matrix for the proposed solution.

LET’S BUILD TOGETHER

Let’s discuss your
security requirements.

Bring your data-residency, access-control, PCI responsibility and operational resilience requirements into solution scoping.